Abstract

Cyberattacks have become more frequent and more violent in recent years. To date, defensive infrastructure has been relatively static, and security functions are usually placed in a common order that does not depend on the current situation. We propose the concept of attack-aware Security Service Function Chain reordering. The idea is to change the order of security functions depending on the malicious traffic observed. We present the basic idea, evaluate the impact of the function chain order, and introduce a framework for function chain reordering. Our evaluation shows that the order often has a significant impact on the performance of the security function chain and that there is no single order that outperforms all other orders in every situation. The proposed proof-of-concept framework successfully validates the feasibility of attack-aware security function chain reordering, and we propose additional extensions to eliminate the remaining deficiencies.

Links and resources

Tags

community

  • @se-group
  • @luk.ifflaender
  • @lukas.beierlieb
  • @samuel.kounev
  • @michael_stenger
@se-group's tags highlighted